Privacy policy

As of September 2026

This English version is provided for convenience. The German version is legally binding.

Privacy policy

1. Controller

HTMLHELD is a service of Alphaformat UG (haftungs­beschränkt). The controller responsible for processing personal data on this website is:

Alphaformat UG (haftungs­beschränkt) Ohlmüllerstr. 14 81541 München

Office: Freibad­straße 30, 81543 München Represented by the Managing Director Stefan Levin Email: info@htmlheld.de

2. Overview

  • This website does not set any cookies. We do not use tracking, analytics tools or adver­tising.
  • We load fonts and icons from our own server. When you visit our pages, your browser does not connect to Google or any other third-party provider. The booking calendar also runs on our own server.
  • Beyond that, we only process personal data when you write to us, book a call, conclude a maintenance contract or otherwise enter into a business rela­tion­ship with us, so that we can fulfill our contrac­tual oblig­a­tions.

3. Legal bases

We process personal data on the following legal bases of the General Data Protection Regulation (GDPR):

  • Contract (Art. 6(1)(b) GDPR): Processing is necessary for a contract with you or for pre-contractual measures taken at your request.
  • Legal obligation (Art. 6(1)(c) GDPR): Processing is necessary to comply with a legal obligation, such as a reten­tion oblig­a­tion.
  • Legitimate interests (Art. 6(1)(f) GDPR): Processing is necessary to protect our legitimate interests, unless your interests and fundamental rights over­ride them.

Each of the following sections states which legal basis applies to which processing.

4. Hosting and server log files

For this website, our support system, our domains and our emails we use the infra­struc­ture of two providers: Hetzner Online GmbH, Indus­triestr. 25, 91710 Gunzen­hausen, Germany, and webgo GmbH, Wenden­straße 8-12, 20097 Hamburg, Germany. The servers are located in Germany. We have concluded data processing agreements with both providers pursuant to Art. 28 GDPR. To the extent that the providers also process data under their own respon­si­bility, for example for the operation and security of their data centers and networks, we have no influence on this. The privacy notices of Hetzner and webgo apply to that processing.

Each time a page is accessed, the server auto­mat­i­cally stores the following data in log files (server log files):

  • IP address
  • date and time of access
  • page accessed
  • browser type and browser version
  • operating system
  • referrer URL (the page visited before)
  • host name of the accessing computer

This data is technically necessary to deliver the website and to ensure its secure and stable operation. We do not combine it with other data sources. The legal basis is Art. 6(1)(f) GDPR. The server log files are deleted auto­mat­i­cally after 14 days at the latest.

5. Contact form and email

When you write to us using the contact form, we process:

  • name, email address and phone number
  • website address
  • your message
  • time of the request, IP address and browser iden­ti­fier

We only receive this information if you fill in and submit the form yourself. We point this out above the submit button. We store it on our server and in our backups and use it only to handle your request and any follow-up questions. We do not pass it on to third parties. If you write to us by email, the same applies to your message and the information it contains. Our mailboxes and the sending of our emails, such as appointment confir­ma­tions, are operated on our behalf by an email service provider with servers in Germany.

The legal basis is Art. 6(1)(b) GDPR if your request concerns a contract with us or its initiation, otherwise Art. 6(1)(f) GDPR (our interest in answering requests). We store the time, IP address and browser identifier for technical reasons only, on the basis of Art. 6(1)(f) GDPR, to prevent misuse of the form and to be able to prove receipt of a request. We do not analyze them.

The data remains with us until you request its deletion or the purpose no longer applies. Statutory retention periods remain unaf­fected.

6. Booking a call

On the Contact page, you can book a meeting directly with us. The calendar runs on our own server; no data is transferred to third parties.

In doing so, we process your name, email address and phone number, the type of call you choose (phone or video), the date and time, the address of your website and your request, as well as the time of the booking and of its confir­ma­tion. To protect against misuse, we store your IP address and browser identifier with the booking (Art. 6(1)(f) GDPR); we do not analyze them.

After booking, you receive an email with a link to confirm or cancel the appointment. If the appointment is not confirmed, it expires. Before a confirmed appointment, we send you reminders. If the call takes place by video, we use a room at Whereby (Video Commu­ni­ca­tion Services AS, Norway); the connection is only established when you open the link to the call, and the Whereby privacy notice then applies.

The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures at your request). We delete the booking data six months after the appointment, after a cancel­la­tion or after expiry. If a contract results, the periods set out in section 7 apply.

7. Concluding the maintenance contract online

On the Conclude a main­te­nance contract page, you can conclude a maintenance contract online. This also applies when you add another website to maintenance in the customer area. In doing so, we process:

  • the information you enter in the form: company, name, billing address, email address, phone number, VAT ID, website address, access details for WordPress, FTP and hosting, and any special notes
  • the plan you choose and the way you choose to conclude the contract
  • when concluding directly or by signature: your signature as an image (if you draw it), time, IP address, browser identifier, the contract text with checksum (SHA-256) and a PDF of the signed contract generated from it, including proof of conclu­sion
  • when concluding by PDF: the file you upload

The checksum proves that the stored contract text has not been changed afterwards. We only generate the PDF with your information for printing if you request it. It is not stored.

We process this data to conclude the contract, to prove its conclusion and to set up the maintenance. The legal basis is Art. 6(1)(b) GDPR. For proof of the conclusion of the contract, Art. 6(1)(c) GDPR (statutory retention obligations) and Art. 6(1)(f) GDPR (our interest in being able to prove the conclusion of the contract) also apply.

We store the data for the term of the contract and thereafter for as long as the statutory retention periods under commercial and tax law require, i.e. up to 10 years. We delete the access details for WordPress, FTP and hosting when the contract ends.

8. Customer area

The customer area with the ticket system is a separate application. A separate privacy policy applies to it.

9. Data security

In accordance with the legal require­ments, we take appropriate technical and orga­ni­za­tional measures to ensure a level of protection appropriate to the risk.

This website uses SSL or TLS encryption. You can recognize an encrypted connection by the fact that the address bar of your browser begins with “https://” and shows a lock icon.

10. Your rights

Under Art. 15 to 21 GDPR, you have the following rights with respect to us:

  • access to the data we store about you (Art. 15 GDPR)
  • recti­fi­ca­tion of inaccurate data (Art. 16 GDPR)
  • erasure of your data (Art. 17 GDPR)
  • restriction of processing (Art. 18 GDPR)
  • data portability (Art. 20 GDPR)
  • objection to processing (Art. 21 GDPR)

Right to object: Where we process data on the basis of Art. 6(1)(f) GDPR, you can object to this processing at any time on grounds relating to your partic­ular situ­a­tion.

There is no automated decision-making, including profiling (Art. 22 GDPR).

To exercise your rights, write to info@htmlheld.de.

You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is:

Bayerisches Landesamt für Daten­schutza­uf­sicht (BayLDA) Promenade 18 91522 Ansbach

11. Changes to this privacy policy

We update this privacy policy when our website, our processing or the legal require­ments change. The version published here at the time applies.